Privacy Policy
Last updated: August 10, 2026
TradeAssay ("the App", "we", "us") is a personal trade-journaling application. This policy explains what data we collect, why, and how you can control it.
1. Who we are
TradeAssay is developed by an independent developer. Contact: support@tradeassay.com.
2. Data we collect
| Data | Why we collect it | Required? |
|---|---|---|
| Email address | Account creation and login (Supabase Auth) | Yes |
| Password | Account authentication (stored hashed by our auth provider, never in plain text, never seen by us) | Yes |
| Trade records you enter | Symbol, direction, entry/exit price, stop-loss, position size, commission and swap, date/time, strategy, emotion, session, notes — this is the core journaling data you provide | Yes, to use the App |
| Your playbooks | The setups you define and the rules you set for them — entry criteria, allowed sessions, a maximum number of trades per day, a maximum position size. Kept so the App can show you how often you followed your own rules. Every structural edit is versioned, so a rule you changed in June is still compared against the trades you took in June rather than being silently rewritten | Optional |
| Trade reviews | When you re-judge one of your own past trades with the outcome hidden, we store your verdict and any note you attach, so the App can compare what you thought at the time with what you think now | Optional |
| Trade screenshots (Pro) | If you choose to attach a screenshot to a trade, it is uploaded to our storage provider | Optional |
| App settings | Timezone, language, account balance, risk limits you configure — used to personalize calculations shown to you | Yes, to use the App |
| Subscription status | Whether you have a free or Pro plan, so the App can unlock the right features | Yes |
| Voice notes (Pro) | If you record a voice note against a trade, the audio clip is uploaded to private storage and sent for automatic transcription. Recording only ever starts when you press the microphone button — never in the background | Optional |
| Product analytics events | A short, fixed list of named events (signed up, logged a trade, viewed the upgrade screen, subscribed) tied to your account ID, so we can see where the App is confusing or broken | Yes |
| Crash and error reports | Stack traces when something fails, tied to your account ID, so we can fix it | Yes |
We do not collect location data, contacts, browsing history outside the App, or advertising identifiers. We do not sell your data, we do not use it to train any AI model, and we run no advertising trackers.
Our analytics deliberately exclude autocapture and session recording — the two features that would otherwise silently record your screen contents. Because this App's screens are full of account balances and P&L figures, those are switched off in code, and only the explicitly named events listed above are ever sent.
3. How data is stored
All data is stored in a Supabase (PostgreSQL) database with row-level security enabled — each account can only ever read or write its own data. Screenshots and voice notes are stored in Supabase Storage; the voice-note bucket is private and access is restricted to your own account. Data is transmitted over encrypted (HTTPS/TLS) connections.
4. Who we share data with
We do not sell your data. We share it only with the service providers needed to make specific features work:
| Provider | What is sent | When |
|---|---|---|
| Supabase | All of your account data | Always — this is our database, authentication and file storage |
| Vercel | Web hosting requests | Always — this is where the App is served from |
| Anthropic (Claude) | Statistics and notes from your trades | Only when you generate an AI coaching report or chart analysis |
| Groq | Statistics and notes from your trades | Only when you use the journal chat or receive a weekly debrief |
| OpenAI (Whisper) | The audio clip you recorded | Only when you record a voice note, for transcription |
| MetaApi | Nothing — this is currently switched off | Never, at present — see section 4a |
| Sentry | Crash reports with your account ID | When an error occurs |
| PostHog | The named product events listed in section 2 | On those specific actions |
| Google Play / Stripe | Payment is handled entirely by them | At purchase — we receive only your subscription status, never your card details |
Two things are deliberately kept out of everything above: your playbook rules and your trade reviews are never sent to any AI provider. They stay in your own database rows and are only ever read by the App's own calculations, which run on your device. Your recorded position sizes are not sent either.
4a. Broker passwords — we don't ask for one
Live broker sync is switched off, and the App does not ask you for a broker password of any kind. Trades get in by manual entry or by importing a report you export yourself (MT4/MT5, CSV, HTML, XML). An exported report is just a file — it carries no credential, so there is nothing for us or anyone else to hold.
MetaApi is still named in the table above because the integration code remains in the App, switched off. While it is off, MetaApi receives nothing from us. If it is ever switched back on, this page will be updated before it is, and connecting an account will stay something you choose to do, never a default.
For the record, the design it would return to: the App would ask only for the read-only investor password — which can view an account but cannot place, modify or close a trade, and cannot withdraw funds — never the master password. That password would never be stored in our database, encrypted or otherwise; it would pass through our server once, in memory, on its way to MetaApi. If our database were breached, there would be no broker credential in it to steal.
5. Your controls
- You can export all your trade data at any time from within the App (JSON, CSV and PDF export).
- You can delete individual trades, screenshots and voice notes at any time.
- You can permanently delete your entire account and all of its data — from inside the App (account menu → "Delete my account"), or from this page without needing to install the App. Deletion is immediate and irreversible; we do not freeze or deactivate accounts in place of deleting them.
- You can change your timezone, language and settings at any time in-app.
6. Data retention
We retain your data for as long as your account exists. When you delete your account, your database records and uploaded files are erased immediately as part of that request. If you email us instead of using the in-app or web deletion route, we action it within 30 days.
Anonymous, aggregated diagnostics that can no longer be linked to you may be retained. Payment records held by Google Play or Stripe are subject to their own retention rules and are outside our control.
6a. This is not financial advice
TradeAssay analyses trades that you recorded yourself. It is a journaling and performance-analysis tool. Nothing it produces — including AI coaching reports, weekly debriefs and chat answers — is financial, investment or trading advice, and past performance does not predict future results. We are not a broker, a financial adviser, or regulated by any financial authority.
7. Children's privacy
The App is not directed at children under 13, and we do not knowingly collect data from children.
8. Changes to this policy
We may update this policy as the App evolves. Material changes will be reflected by updating the "Last updated" date above.